Penetration Testing Manager, Devices & Services Penetration Testing

Job Description


Amazon’s Devices & Services Penetration Testing Team is seeking a Penetration Testing Manager to lead a team of expert security engineers who conduct offensive security assessments of Amazon’s most innovative devices and services…

This role will provide you with challenging leadership and technical opportunities, but will also be a great deal of fun if hacking Amazon’s newest products sounds exciting to you!

You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to drive improvements to services, processes, and technologies throughout the company, with the ultimate goal of ensuring the continued safety and security of our customers.

You will be focused on using your leadership and technical skills to continually lead the direction and evolution of the team and orchestrate penetration testing engagements in order to maintain and raise Amazon’s high security bar. Additionally, you’ll be driving strategic initiatives from your team by influencing key stakeholders and partnering with teams throughout Amazon to enable the implementation of innovative security solutions and controls to improve Amazon’s security and software development posture.

You’ll be supported by a team of highly skilled security engineers focused on attacking Amazon from a variety of perspectives, all working with a singular focus on maintaining our customer’s trust. You must also demonstrate resilience and navigate ambiguous situations with composure and tact. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its Customers secure.

Key job responsibilities
• Lead, manage, and develop a high performing technical Penetration Testing Team across multiple locations
• Manage and coordinate complex penetration testing projects involving multiple security engineers, technology stacks, and development teams
• Lead the strategic direction and evolution of the Penetration Testing Team, including setting goals and establishing priorities
• Drive strategic initiatives by influencing leadership, key stakeholders, and partnering with teams throughout Amazon
• Lead effective teamwork, communication, collaboration and commitment across multiple disparate groups with competing priorities
• Lead improvements to internal program and process
• Write and deliver high-quality documents for technical and non-technical audiences

A day in the life

The internal penetration testing team is part of the Devices and Services Trust & Security organization, which is responsible for ensuring the security of Amazon Consumer Devices including Kindle, Ring, FireOS, Kuiper, Alexa, eero and more.

The team is responsible for reviewing these products, and their associated service layers, with focus on penetration testing, fuzzing and vulnerability research.

Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.

About the team

About Amazon Security

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build

experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

We are open to hiring candidates to work out of one of the following locations:

Arlington, VA, USA | Austin, TX, USA | Bellevue, WA, USA | New York City, NY, USA | Sunnyvale, CA, USA | Virtual Location – USA

Basic Qualifications
• 3+ years of experience in a technical security leadership role
• 5+ years of experience in Information Security related domains, with knowledge of security fundamentals, application vulnerabilities, application attack vectors, penetration testing methodologies, and tools
• 3+ years of experience driving Information Security initiatives across large diverse organizations
• Experience communicating with a wide range of technical & non-technical partners and senior leadership

Preferred Qualifications
• Experience with driving remediation/mitigation of security issues and control gaps
• Ability to take ownership of program ambiguity, mitigate risk, and produce results
• Experience gathering and reporting metrics to measure service and program effectiveness and consistency
• Technical knowledge of adversary Tactics, Techniques, and Procedures (TTPs)
• Understanding of and experience in pentesting Operating systems, Firmware, Bootloaders, etc.
• Experience with cloud service providers and their offerings, preferably AWS, and its various technologies and services
• Knowledge of system or security design approaches with experience driving engineering and architectures to deliver results

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $140,100/year in our lowest geographic market up to $272,400/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit This position will remain posted until filled. Applicants should apply via our internal or external career siteShow full descriptionCollapse